19 ms·
Since this news broke a few weeks ago, I've seen many people suggesting that Apple miscalculated and might be surprised by the push-back they're receiving; that
by dmitryminkovsky 5y ago
Since this news broke a few weeks ago, I've seen many people suggesting that Apple miscalculated and might be surprised by the push-back they're receiving; that some misunderstanding may have occurred.
I find exceedingly difficult to imagine that one of the most sophisticated companies in the world, with some of brightest minds out there, did not consider and calculate this precisely; that there is any way any of this has come as a surprise to Apple. Extending Apple the benefit of doubt does not seem possible in this case.
Yesterday we saw OnlyFans exit the adult industry. Two weeks ago we saw Apple exit the privacy industry.
EDIT:
Some are questioning whether Apple was ever in the privacy industry. That's a good question. Even though their devices were certainly not secure and could be compromised, I think they were certainly in the privacy industry in the sense that they marketed an intention to make their devices as private and secure as possible[0]. Which is basically all a consumer can ask from a computer company.
[0] https://9to5mac.com/wp-content/uploads/sites/6/2019/01/DwGoq2uV4AA_Aov.jpg-large.jpeg?quality=82&strip=all&w=1600 https://9to5mac.com/wp-content/uploads/sites/6/2019/01/DwGoq...
- userbinator 5y agoA popular theory is that this was motivated by the government somehow, and they had to comply by hiding it under the guise of something else.
- deleted 5y ago[deleted]
- WORMS_EAT_WORMS 5y agoIt could be the other way around. Interesting thoughts: https://mobile.twitter.com/benadida/status/1424764923717066758 https://mobile.twitter.com/benadida/status/14247649237170667... > I don’t see a huge threat to privacy, but I’m not sure how this meaningfully stops CSAM. My guess: Apple is trying to stave off more heavy-handed gov intervention. Thread:
- dmitryminkovsky 5y ago> Apple is trying to stave off more heavy-handed gov intervention. This is an interesting and charitable interpretation, but if so, then this tactic will fail. As others here have pointed out: with this capability in place, the only thing stopping them from total intrusion is now merely policy. And that's scary and dangerous.
- WORMS_EAT_WORMS 5y agoYeah and FYI it is not my position on the issue and adding because I found the thread curious. I just can’t even begin to imagine what a gigantic company like Apple’s real government relations are like however.
- matwood 5y agoI think what is making people uncomfortable is the realization it's always been policy.
- Macha 5y agoYou could argue that it's policy to develop or not develop this feature, but if the feature doesn't exist, you could always refuse the update that provides it, whereas if apple adds tiananmen-square.jpg to this list in China after the feature is out there, then you don't know until you're already screwed.
- matwood 5y agoThe list is only updated with new versions of iOS. So if that's a concern wait until new versions are compared against old prior to updating. Downloading the list outside an iOS update would be a new 'feature' just for China. If we're in that mode, then Apple could also have just added scanning for only China. Finally, the list is an intersection from at least two jurisdictions. I think there is plenty of good debate to have around this feature, but I also think it's important to start with the discussing the feature as is today.
- headShrinker 5y agoThere is big talk of a federal anti-trust against Apple. The rumors have been swirling for months. Apples CSAM initiative might be an attempt to cool things off at the justice department. https://www.marketwatch.com/story/apples-hot-antitrust-autumn-storm-clouds-are-forming-from-multiple-directions-11628711809 https://www.marketwatch.com/story/apples-hot-antitrust-autum...
- dahfizz 5y agoWhat does CSAM have to do with anti-trust suits?
- vegetablepotpie 5y agoWhat does politics have to do with politics?
- MerlinDE 5y agoAnti child abuse measures are regularly utilized to push for measures you otherwise can‘t establish. Most of the time surveillance and censorship. Just look back 10+ years to Germany, where „Zensursula“ tried to establish DNS blocking for the media industry by arguing for child safety. The approach is always the same. Just this time, Apple has so many devices in the market, that if this succeeds we‘ll all be headed for surveillance disaster. Given that fact that Snowden’s revelations didn’t generate ANY actions within the public, I doubt to see any actions this time.
- wpietri 5y agoTwo things. One is political give and take. As their people negotiate with particular political actors, "We'll give you nothing," works much less well than, "We can't give you X, but how about Y?" The other is that the tech giants are looking unaccountable and antisocial. Privacy absolutism is popular here, but there are real social costs to it, so it's not popular everywhere. If Apple can say, "Yes, privacy is important, but we're not crazy; we agree we don't want to help out child pornographers", then that is much better positioning.
- 5y ago
- ryeguy_24 5y agoCould it be that Apple thought that child pornography was going to get the most sympathy from society for this general approach of scanning libraries? They may have expected some HN push back but maybe hoped for some halfway decent press related to helping combat this abuse. I ask that question in curiosity but I'm super skeptical because this is actually surveillance.
- sk2020 5y agoThe implementation also means Apple has plausible deniability if the “CSAM” in their database actually contains images associated with political enemies of whatever regime supplies the source material. How would you know the hash you are testing against isn’t just a Winnie the Pooh? You really can’t. Really, it’s probably the best way to keep the police state from destroying your business while trying to sleep at night.
- Covzire 5y agoHow long has the government been telling everyone to implement back doors into their ecosystems that only law enforcement can access?
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- sandworm101 5y ago>> that one of the most sophisticated companies in the world Microsoft Zune. The Super League. 47 Ronin. Wonder Woman 1984. Google+. Big companies make big mistakes. No matter how many focus groups you collect, no matter how many phone surveys you do, things can go wrong.
- version_five 5y agoI read an argument that Zune was essentially MS showing RIAA et al how bad a product that met all their DRM demands would be. No idea if its true, but I find it interesting.
- sandworm101 5y agoIn that field, the biggest mistake is probably Sony BMG shipping a root kit on music CDs. That certainly showed the world how bad an RIAA-endorsed product could become. It made napster-downloaded MP3s the safer option, accelerating filesharing immensely amongst computer owners. https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootkit_scandal https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk...
- version_five 5y agoYes, that whole era was about tech companies trying to balance demands from traditional distributors who had lost their power, and consumers that wanted the freedom they digital media provides. There were many missteps and retrospectively terrible products and business models that were tried before be got to where we are today. I wonder of the same is true re (broadly) government power. Tech companies are now balancing the power governments and other stakeholders would like them to wield with what people will tolerate. Its not really a surprise there are missteps again.
- fatnoah 5y agoI think a big difference between Zune and Apple's CSAM issue is that there were people (literally dozens of us!) who LOVED the Zune.
- realusername 5y ago> I find exceedingly difficult to imagine that one of the most sophisticated companies in the world, with some of brightest minds out there, did not consider and calculate this precisely; that there is any way any of this has come as a surprise to Apple. Extending Apple the benefit of doubt does not seem possible in this case. Why is that so difficult to imagine? Apple's security model has always been "just trust us and don't question it", questioning their own practices themselves just has never been done. That's already what's happening with any other Apple software, their own services are off limit of their model, explicitly excluded & explicitly trusted. This opinion is also reflected in their security threat document they published, they never talk about themselves being in the list of potential threats. That's just in the continuity on how they usually work.
- blubapabedo 5y agoI think you’re overestimating Apple’s forethought. Remember, they gave us the butterfly keyboard.
- imchillyb 5y agoThe butterfly keyboard was an IBM Thinkpad invention, until other companies copied the design for their own flagships.
- AlexandrB 5y agoIt's easy for a large company, especially its leadership, to be out of touch with their customers. Many instances of this are listed in another reply, but it's not all that unusual. I would definitely believe that Apple thought this solution was more private than the kind of scanning Google and Facebook does. Especially now that they're drinking their own cool-aid about being a "services" company where the line between "my device" and "your cloud" starts to blur. Edit: It's also notable that news of this was leaked before Apple was able to officially announce anything. This means that Apple's marketing department was not able to control the tone/narrative as well as they normally do. The first thing many people heard was "Apple will be scanning your phone" without any of the nuances that came later.
- lupire 5y agoWhy so you use the word "cool aid" to describe a fact about objective reality? iPhone is packed with software literally named "Digital Rights Management"
- deleted 5y ago[deleted]
- version_five 5y agoWe've seen a recent wave of big tech companies moving into quasi government roles in relation to censorship and rule enforcement. The apple thing is in keeping with the general trend.
- kalleboo 5y agoA lot of that is fueled by fear of actual government roles taking charge. Tech companies have been left unregulated for so long and now governments have noticed how pivotal they are, that tech companies are trying desperately to head off regulation with self-regulation. Just look at the mixed reactions to GDPR here on HN to see how controversial is it when governments do actually regulate things, it's not hard to understand that tech companies are eager to head that off.
- gjsman-1000 5y agoOne speculated motive is that Apple wanted an End-to-End Encryption system for iCloud, but the FBI put immense pressure in 2018 internally to shut that project down because it could spread CSAM, among other things. Then in 2020, there was the EARN IT Act proposal, which nearly passed and would have required scanning for CSAM on pretty much every online platform that wanted Section 230 immunity. Apple puts two and two together, realizes Congress is concerned about CSAM's spread and isn't interested in changing, and still wants E2EE on iCloud. OK, put the scanning client-side, then the way is paved for E2EE iCloud because the FBI's biggest argument against E2EE is neutralized, and so is Congress' argument for EARN IT (which would basically have banned E2EE).
- matwood 5y agoIf you haven't seen it already, this is a good read about EARN it and the issues around CSAM scanning in general wrt the 4th amendment. http://cyberlaw.stanford.edu/blog/2020/03/earn-it-act-unconstitutional-fourth-amendment http://cyberlaw.stanford.edu/blog/2020/03/earn-it-act-uncons...
- Grustaf 5y agoI think most people in general think this is a great idea, tech twitter is an echo chamber.
- dmitryminkovsky 5y agoIf iCloud is not end-to-end encrypted, why is this necessary? I mean, why can't they scan content on ingress?
- Grustaf 5y ago1. They don't want to know anything about the result of the scanning until you have 30 matches. This way is much more private. 2. If they scanned iCloud, they could never start encrypting that.
- shuckles 5y agoThere is also no transparency if the scope or depth of iCloud scanning increases.
- nthj 5y agoI’ve seen a few researchers raise the idea that moving this scanning to the client is effectively a political prerequisite for enabling iCloud E2E, so I suspect that may be coming.
- merpnderp 5y agoWe have no evidence this is true, and Apple has certainly not taken any of the plethora of oppurtunities they've had to make this argument. So there's no reason to believe this to be the case.
- alfiedotwtf 5y agoRemember when Apple pushed U2's new album to everyone as a "gift" and there was backlash?
- wpietri 5y agoI think you're underestimating the degree to which companies have their own internal logic that has nothing to do with the external reality. That tendency increases the larger a company grows. If you're in a one-room house, you can always see outside. If you're inside a giant office building, mostly you see the building. Did somebody raise the concern of push-back? I'm sure. But the moral questions around CSAM are something that was settled long ago internally. When I was at Twitter fighting abuse, the CSAM stuff was a separate group. My boss called them The Department of Mysteries because we almost never saw them or spoke to them. It was led by a serious person, an ex-FBI agent or something like that. They did what they did and we were all ok with it and grateful for it, because that shit is horrific and we didn't want it on our platform and we didn't want to have to deal with it ourselves. My cousin was a PO for sex offenders, and one of our regular discussion topics at family reunions was how sex offenders were way more technologically savvy than a state parole department. How they really needed more help in making sure offenders weren't reoffending while on parole, while also not forcing them to just not use computers and phones altogether. If even I've heard this, I'm sure that Apple execs have heard it from law enforcement a zillion times. It's also clear Apple put a lot of thought into addressing the privacy concerns for this. Technologically, it's sophisticated, impressive. So I can easily believe the people at Apple said, "Sure, there are reasonable concerns, but we think we have addressed them." And that they're surprised by the level of sustained pushback.
- dmitryminkovsky 5y agoThank you for this perspective. I've never worked at an organization of this magnitude, so I am definitely lacking some perspective. > It's also clear Apple put a lot of thought into addressing the privacy concerns for this. Technologically, it's sophisticated, impressive. I'm not sure about this. How is a perceptual hash sophisticated and impressive given that it can be abused by governments demanding Apple scan for political content, etc?
- gjsman-1000 5y agoApple says their protection against authoritarian governments is that an image must appear in two or more government CSAM databases to be scanned. So if a corrupt politician adds something to the database, it won't be scanned unless a different government adds the same image. Now, will China follow this? Probably not. But Apple's defense there is that China could have directly ordered them to build this scanning tool at anytime in the last decade anyway. It's not like China has a magical new tool for invading privacy when they could have (and actually have) just ordered tools to be built as desired.
- red_admiral 5y ago> Yesterday we saw OnlyFans exit the adult industry. Two weeks ago we saw Apple exit the privacy industry. One of those two statements I disagree with. Apple exiting the privacy industry would look like this to me: "we've decided from now on that, like almost all other cloud providers, we'll give ourselves access to your stuff for (ahem) legitimate purposes". Not like this: "we'll implement a neuralhash on the client device rather than on the servers, and then do a cryptographic private-set-intersection protocol with them on the server". That's a lot of cost and effort to prevent themselves, as a company, misusing the CSAM detector for other purposes. If there are government agencies involved, Apple is also making sure that they can't just use this as a backdoor to get access to everyone's files, it's as if the government said "we need to prevent child abuse, give us a backdoor" and Apple went "ok we'll give you a small backdoor that's ok at detecting abuse images and nothing more" - if the government was expecting to use the backdoor for more than this, they'll be disappointed. (I'm pretty sure they have other backdoors already, by the way. My guess would be a zero-day on the baseband processor firmware.) I'm not saying I agree or disagree with Apple's latest move, but "exit the privacy industry" feels a bit a strong statement to me. You have less privacy than you did three weeks ago, and an option on even less privacy in the future (but then again Apple could just change the T&C), but you're still better off than with competitors that offer similar functionality.
- matthewdgreen 5y agoI think many at Apple really are surprised by this, and I put it down to a failure of elite consensus. I think that a number of folks at high levels in the SV executive suite have accepted a manufactured consensus along with their peers in Washington, and that consensus is something like: "people don't care about the privacy of what's on their device and they'll put up with anything to stop CSAM, even if it means scanning personal backups and local files (as opposed to shared files.)" This seems like a reasonable thing to believe, since server-side scanning of (mostly shared) files has been going on for years and nobody has pushed back very hard on it. But what I think the consensus missed is that the reason for this lack-of-pushback is that nobody in the wider world had really been asked to weigh in on it before. It was something that a few elite tech busybodies were aware of, and most people accepted the idea that providers needed to check out photos that lived (unencrypted) on their servers. Apple accepted this logic and extended it unthinkingly beyond shared photos to unshared private photo libraries on the user's personal device (even if they are staged for backup as part of the iCloud Photos synchronization service, which is just a policy choice.) This was a second mistake because it assumed that because users mostly ignored the scanning of shared server-hosted files, they had somehow given consent to having their private files searched on their device. I don't think they had. Overall, this announcement is the first time anyone has attempted to have an actual public debate to see how real users feel about this kind of surveillance, particularly automated surveillance of private photos (and an automated system with potential flaws.) Apple's mistake here was to assume that their user base had already given consent -- when they'd just never been asked. It's a very human mistake to make, frankly. The question is whether Apple will listen to their users or if they'll double down and push this through against their users' pushback. I can forgive Apple for misunderstanding their users once, but continuing down this path will be a lot harder to understand. ETA: To illustrate how much more pervasive Apple's surveillance is than the standard (ignoring the PSI protocols), consider this quote from an EU Parliament briefing: "Others, such as Dropbox, Google and Microsoft perform scans for illegal images, but 'only when someone shares them, not when they are uploaded'." (I can only trust that this is factually true.) In this sense, Apple's move to scan all photos in your library is a significant functional escalation.) https://www.europarl.europa.eu/RegData/etudes/BRIE/2020/659360/EPRS_BRI(2020)659360_EN.pdf https://www.europarl.europa.eu/RegData/etudes/BRIE/2020/6593...
- egypturnash 5y agoIt seems that a large part of why OnlyFans is destroying itself is an attempt to comply with some incredibly onerous requirements that MasterCard added in April: https://www.xbiz.com/news/258606/heres-what-the-new-mastercard-rules-mean-for-adult-sites-producers https://www.xbiz.com/news/258606/heres-what-the-new-masterca... Especially “all content must be reviewed for child porn before publishing, or in real time if streaming”. It now seems not at all implausible that Apple’s half-baked attempt to scan everything for child porn is due to this too.
- hughrr 5y agoI think you’re misunderstanding the ability for an echo chamber corporation to fuck itself thoroughly on that one. They have serious problems admitting they did something stupid historically. Butterfly keyboards, reliability issues, you’re holding it wrong etc.
- kalleboo 5y ago> I find exceedingly difficult to imagine that one of the most sophisticated companies in the world, with some of brightest minds out there, did not consider and calculate this precisely; that there is any way any of this has come as a surprise to Apple After having read a lot of internal Apple emails between executives[0], I find it extremely easy to imagine that they were completely dumbfounded that the rest of the world did not see things the same way they did. [0] https://twitter.com/TechEmails https://twitter.com/TechEmails
- browningstreet 5y agoI’ll note reports that Apple significantly increased iPhone manufacturing volume for the new phones coming out this fall. I hope it continues to be interesting to see what happens next.